Endpoint Engineer, EDR (linux)

Posted Yesterday
Be an Early Applicant
Hiring Remotely in USA
Remote
Expert/Leader
Artificial Intelligence • Software • Cybersecurity
The Role
Build and maintain Linux endpoint detection and response sensors using kernel and user-mode components, eBPF, LSM, and audit subsystems. Develop high-fidelity detection and prevention, anti-tamper protections, telemetry, performance optimizations, and automated testing. Investigate severe customer escalations involving crashes, hangs, regressions, and missed detections. Collaborate across security research, AI, platform, and product teams while mentoring engineers and supporting release quality and on-call responsibilities.
Summary Generated by Built In
Endpoint Engineer, EDR (linux)

About Ent

Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We’re now hiring the team that will define this category.

How We Work

Customer first. The product and the business are built around problems we’ve watched real security teams struggle with — not the other way around. Every roadmap conversation starts with what a CISO told us last week.

Humble. No drama. We hire people who share the mission and trust each other to deliver. Teamwork over showmanship. Accountability over politics. The work speaks louder than the person doing it.

Urgency. The window to build a durable security company in the AI era is open right now and it will not stay open. The shot clock has started. We move at the speed of the people we want to protect.

About the Role

We are seeking an Endpoint Engineer to be part of the team that owns the Linux sensor at the core of Ent's EDR capability. This role builds detection and prevention on eBPF, LSM, and the audit subsystem, across the range of Linux customers actually run — workstations, servers, containers, and cloud workloads. You will own the tradeoffs between detection efficacy, false positives, and performance, and defend them with measured data.

What You’ll Achieve
  • Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Linux and turn that activity into high-fidelity intent signals.

  • Own EDR-class detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before it completes.

  • Make and defend explicit tradeoffs between detection efficacy, false-positive rate, and endpoint performance, backed by measured data rather than intuition.

  • Instrument telemetry at the OS boundary: eBPF, LSM, and audit subsystems.

  • Harden the agent against tamper, bypass, and evasion — self-protection, integrity validation, and safe handling of untrusted input inside a privileged process.

  • Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions before they ship.

  • Build test harnesses, automated regression coverage so every efficacy claim is continuously verified, not asserted.

  • Drive high-severity customer escalations to root cause — crashes, hangs, performance regressions, missed detections — at the code and OS-internals level, and convert escalation patterns into permanent fixes.

  • Partner with the security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement, just-in-time interventions, and investigation timelines.

  • Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call.

What You’ll BringMust-haves
  • 10+ years designing, building, and delivering production C/C++ (or Rust) systems software, a substantial portion of it in endpoint security, OS internals, or comparable performance-critical native code.

  • Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.

  • Hands-on production experience with eBPF.

  • Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering.

  • Practical fluency in attacker TTPs; you can reason about what an attack looks like in raw telemetry, not just in a written report.

  • Strong low-level debugging skills, performance tracing, and crash-dump analysis.

  • Multi-threaded and concurrent programming under load — synchronization, lock contention, race conditions, and object lifetime management.

  • A track record of code running on large fleets without degrading end-user experience; you treat stability and performance as product features.

  • Scripting fluency for tooling and test automation (Python or equivalent).

  • Clear written and verbal communication with distributed teams and, when escalations demand it, directly with customers.

Bonus
  • Kernel-mode driver or kernel extension development shipped to production at scale.

  • Reverse engineering, malware analysis, or exploit and vulnerability research background.

  • Experience with anti-tamper and code integrity.

Our Benefits
  • Distributed workplace. While we have positions we hire for in our SF office, we also hire remotely across North America.

  • Own a piece of the journey. Every teammate gets meaningful equity on top of their salary.

  • We’ve got you covered. 90% of your medical, dental, and vision is paid by Ent. We also cover 75% for your dependents.

  • Take the time you need. Our flexible PTO lets you recharge, travel, or just take a breather.

  • Family matters. 12 weeks of fully paid maternity leave (birth, adoption, or foster) and 8 weeks fully paid paternity leave.

  • Live well. A $100 monthly lifestyle account to spend on what keeps you healthy and happy — fitness, wellness, learning, and more.

  • Set up your space. A $500 home office stipend when you join as a remote employee.

Diversity & Accommodations

We’re committed to building a diverse, inclusive, and equitable workplace where people of all backgrounds, identities, experiences, and abilities are welcomed, valued, and supported. We recognize there is no single path to success and value nontraditional career journeys and diverse perspectives as key to building stronger, more innovative teams.

We strive to ensure an inclusive experience at every stage of hiring and are happy to provide reasonable accommodations. If you require accommodations or accessible formats at any point during our process, please let your recruiter know. As an equal opportunity employer, our hiring process is designed to put you at ease and help you do your best work. If there’s anything we can do to improve your experience, we’re always open to feedback.

Skills Required

  • 10+ years designing, building, and delivering production C/C++ or Rust systems software, including substantial endpoint security, OS internals, or performance-critical native code experience.
  • Deep knowledge of operating system internals, including process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.
  • Hands-on production experience with eBPF.
  • Experience building or operating an EDR, EPP, XDR, or antivirus product, or equivalent detection-and-response engineering.
  • Practical fluency in attacker tactics, techniques, and procedures, with the ability to interpret attacks in raw telemetry.
  • Strong low-level debugging, performance tracing, and crash-dump analysis skills.
  • Experience with multithreaded and concurrent programming under load, including synchronization, lock contention, race conditions, and object lifetime management.
  • Experience operating code across large fleets without degrading end-user experience, with emphasis on stability and performance.
  • Scripting fluency for tooling and test automation, using Python or an equivalent language.
  • Strong written and verbal communication skills with distributed teams and customers.
  • Production kernel-mode driver or kernel extension development at scale.
  • Background in reverse engineering, malware analysis, or exploit and vulnerability research.
  • Experience with anti-tamper and code integrity.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
574 Employees
Year Founded: 2025

What We Do

Ent is an intent-aware workspace security platform designed to protect human and AI-driven work. It monitors user, agent, and application activity in real time, interprets intent, and intervenes at moments of risk before incidents occur. Founded by cybersecurity entrepreneurs Lou Manousos and Brandon Dixon, Ent serves Global 2000 customers in hospitality, financial services, and defense, and is backed by leading technology investors.

Similar Jobs

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Senior Casualty Claims Resolution Specialist - Complex Northwest

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
2 Locations
40000 Employees
75K-157K Annually

Dynatrace Logo Dynatrace

Enterprise Account Executive

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Remote or Hybrid
Dallas, TX, USA
5600 Employees
149K-186K Annually

Enverus Logo Enverus

Sales Compensation Specialist - 26356

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
4 Locations
1800 Employees
90K-105K Annually

MetLife Logo MetLife

Principal Data & Analytics Lead

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
140K-210K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account